SAP Security Note
High priority
SAP security note 2099500, "Missing Authorization Check in SPNego Wizard", is a program error note released on February 10, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An authenticated user can use functions of the SPNego wizard to which access should be restricted. This may result in an escalation of privileges.
Solution
Update your Java AS to a Support Package or release where the issue is fixed.
Reason and prerequisites
The SPNego wizard does not contain checks for authorization of the authenticated user to access some of the wizard’s functions. This may result in undesired system behavior.
CVSS
Score 6.5 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
Full note on SAP: SAP Support Launchpad note 2099500
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
